---
id: CVE-2026-55176
title: >-
  Soft Machine is a Virtual Machine–based agentic development environment /
  Cloud OS
summary: >-
  Soft Machine is a Virtual Machine–based agentic development environment /
  Cloud OS. In versions 0.2.247 and prior, two authentication helpers in
  /app/server.js — verifyContainerAuth() and authenticateWorkspaceHttp() —
  accept the global C…
severity: critical
cvss: 9
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-863
vendor: Soft-Machine-io
product: security
affected:
  - security <= 0.2.247
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T19:57:08.043'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55176'
references:
  - url: >-
      https://github.com/Soft-Machine-io/security/security/advisories/GHSA-63gh-vp9f-vxhj
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T17:13:20.838Z'
---

## Overview

Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, two authentication helpers in /app/server.js — verifyContainerAuth() and authenticateWorkspaceHttp() — accept the global CONTAINER_SHARED_SECRET as a bearer token without verifying which workspace the caller belongs to. Because that secret is set identically on every container in the Fly app and is reachable from the user-facing process environment inside each workspace, any tenant can use it to authenticate to any other tenant's workspace API. The result is cross-workspace read, write, and destructive-restore primitives reachable from any paying customer's shell. The existing per-workspace token check (workspaceTokenMatches) protects the user-facing per-workspace token path, but the shared-secret bearer path bypasses it entirely. At time of publication, there are no publicly known patches.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
